CVE-2026-21669: Code Injection
Published Mar 12, 2026
·Updated
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
Affected Software
1 affected component
Veeam Veeam Backup \& Replication>=13.0.0.496<13.0.1.2067
Event History
Mar 12, 2026
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
DescriptionSeverity
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
News Published
via BleepingComputer·04:59 PM
News Published
via BleepingComputer·05:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-21669?
CVE-2026-21669 is considered a critical vulnerability due to its potential for remote code execution by authenticated domain users.
2
How do I fix CVE-2026-21669?
To fix CVE-2026-21669, you should apply the latest security updates provided by Veeam for Veeam Backup & Replication.
3
Who is affected by CVE-2026-21669?
CVE-2026-21669 affects users of Veeam Backup & Replication versions 13.0.0.496 to 13.0.1.2067.
4
What type of attack can be executed using CVE-2026-21669?
CVE-2026-21669 allows authenticated domain users to execute remote code on the Backup Server.
5
Is CVE-2026-21669 easily exploitable?
Yes, CVE-2026-21669 is easily exploitable if attackers gain authenticated access to the domain.